FORENSIA

ATT&CK · T1125

Video Capture

Tactics: collection

About

An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files. Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture video or images. Video or image files may be written to disk and exfiltrated later. This technique differs from Screen Capture due to use of specific devices or applications for video recording rather than capturing the victim's screen. In macOS, there are a few different malware samples that record the user's webcam such as FruitFly and Proton.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

4 known groups

Software

31 malware/tools implement this

DerusbiT9000CrimsonEvilGrabPupyBandookInvisiMoleQuasarRATKazuarjRATAgent TeslaRemcosDarkCometNanoCoreCobian RATEmpireRevenge RATnjRATMacheteZxShellPoetRATImminent MonitorSDBbotTajMahalConnectWiseObliqueRATClamblingWarzoneRATPcShareAsyncRATQuick Assist

Corpus indicators tagged with this technique

78 indicators in the corpus carry T1125.

IndicatorTypeFamilySevSrc
5f3a9ebf7039097b3cdbca8609b5b68af07eeb1dbf716ba2817a97fc7c543854sha256supply_chain801
79c09e1ffb4804c14ff27d41ec08d4390455c92d65717be0aeeec2697297d76asha256supply_chain801
e6e1049158ceb1971c61388349c81fa6047a7aecb4ff2089ef54a50dcc35dbc0sha256supply_chain801
d9f7ca9f93a7d188d51db308877b15d0beae932ca0bf4705384fbedf54b454c1sha256supply_chain801
4d13f1136b13c871c65141b77ec7208488334ac4be511800196adcd328666305sha256supply_chain801
011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972sha256supply_chain801
e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088chash803
3e7066e44132e64360a30974b6ea3671hash803
40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5hash803
2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15dhash803
ab58a90eb3682c6dc3389cd700a64f68a19c0dac3d0fa8e3df97ae041f96d4e1sha256supply_chain801
9a2091e6625fc11cfd8f39c17aa271604e66322ee045028946274b988103e35bsha256supply_chain801
de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2hash803
0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8hash803
3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2dhash803
314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279efhash803
4fcfa88fffacbce30bbe2136753c9ab5a4c092940d2406fd9d44d5118e745b9dhash803
584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8hash803
66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60dhash803
8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0hash803
9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73hash803
a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295hash803
0ffb16209def5500ff4380d9e8093437hash803
900ddb81d27e03967209fee4d17d13deb68eef0e1f10936eb520ca10575cb49esha256supply_chain801
483a36fb9e4aef9704aa1e4edfb88c492dfe4140hash803
d5385526f2f3e52c7d96087611c6cd4e479bf61828400efdb3ca09406d981609sha256supply_chain801
7b2c661cfb69e9c75df90d5102647bb014c28ad5hash803
372f19a45d0eb4c8c52117c6ae2bb8040a91bc72be8670623f957a18c2166985sha256phishing8051
a75eab31d7ff06b6864960ad7e633be3f9730ff3d3873e4539c8f425fc632dadhash803
23808e7638f7a00b1ef9b9f4ca524f8a46cf63be6f6b79fec8e4a3fd1cc82a1esha256supply_chain801

Showing the top 30 by severity of 78.